---
title: "Reclaimed accounts: How do you safely restore customer access after an account takeover?"
date: 2020-11-26T10:12:00+00:00
author: Jessica Allen
canonical_url: "https://www.ravelin.com/blog/restore-customer-account-access-after-ato"
section: Blog
---
Blog /[Ravelin University](/resources?search=&category%5B0%5D=257999#resourceContainer "Go to Ravelin University"), [Account takeover](/resources?search=&category%5B0%5D=134546#resourceContainer "Go to Account takeover"), [Link analysis &amp; graph databases](/resources?search=&category%5B0%5D=134548#resourceContainer "Go to Link analysis & graph databases")

# Reclaimed accounts: How do you safely restore customer access after an account takeover?

After a breach, customers don’t want to lose their accounts and start from scratch. With account takeovers rising against merchants, how can you restore your customer accounts to allow them to safely order again after an attack?

![Reclaimed accounts: How do you safely restore customer access after an account takeover?](https://storage.googleapis.com/ravelin-website-assets-production/assets/images/_blogSmall/214169/280_Restore_customer_access_885_x_505_x2.webp)

When a fraudster gains access to a genuine account, this is known as [account takeover](https://www.ravelin.com/insights/account-takeover-fraud) (ATO), and it carries serious risks for online merchants.

[Ravelin's latest survey of the online fraud landscape](https://pages.ravelin.com/fraud-trends-2024-report) revealed that merchants rate account takeovers as the second worst type of attack against their business. Meanwhile, **ATO attacks have increased against 51.5% of merchants**, with up to 20.2% of merchants reporting a *significant* increase in ATO activity.

Online merchants are being hit with multiple high-impact ATO attacks every month, with certain industries suffering at least one significant attack every week.

The widespread nature of ATO means hundreds or thousands of accounts could be impacted in a single attack.

Losing high volumes of accounts is bad for a merchant, but it’s also bad for the customer if they lose access to an account they have built up over months or even years. What's more, it is likely to negatively affect [customer loyalty and brand image](https://www.ravelin.com/blog/reputation-impact-fraud-brand-image).

## Customers want to reclaim control of their stolen accounts

After an account breach, genuine customers don’t want to have to start from scratch with a new account and lose all their previous order information, favourites or loyalty points.

Plus, if this is the only option available, merchants are at risk of losing a loyal customer to a competitor with a smoother sign-up process – or potentially losing out by offering new sign-up discounts and bonuses to existing customers, which might be bordering on [promo abuse](https://www.ravelin.com/solutions/promo-abuse).

This is why we have ensured you can identify reclaimed accounts in Ravelin. Using the Dashboard, you can send us data to let us know that a customer account has been reclaimed.

This will display on the customer profile and show the date of the reclaim.

![Ravelin account reclaimed](https://storage.googleapis.com/ravelin-website-assets-production/assets/images/Screenshot-2024-12-19-at-14.40.34.png)When you have confirmed that an attack has impacted a genuine customer, we recommend that you also ask the customer to change their password immediately or force a password reset on the account.

Once the password has been changed and the account is fully secure, you can mark the account as reclaimed.

**We strongly recommend that you only enable account reclaims when you are 100% sure that the fraudster has lost access to the account.**

## How reclaimed accounts work

When you mark an account as reclaimed, the system will know and take into consideration that there was a period during which this account was not controlled by its legitimate owner.

This way, the real account owner will not be penalized for actions the fraudster took when they had control of their account, while the activity of the genuine customer themselves will continue to be monitored, as will the security of the reclaimed account.

In practice, a reclaim will:

1. Remove the customer from the ATO network in our [link analysis graph network, Connect](https://www.ravelin.com/blog/connect-ravelin-graph-database-network-analysis-link-analysis), so that the good customer does not remain in the bad network.
2. Reset the rule conditions and features associated with that customer, so that the legitimate customer doesn't get blocked by rules or by a model based on behavior or attributes that were observed during the attack.

In other words, **the ATO detection model will be able to tell that this account is now back with its legitimate owner**.   
  
At the same time, Ravelin will retain all this data, including activity that happened before the reclaim. This means that our models will still take into account genuine customer activity from before the attack.

As a result, you **don’t lose the benefit of using data collected from the customer’s genuine orders and past behavior** on your platform.

## How do reclaimed accounts impact network link analysis?

Our graph database, Connect, allows you to quickly spot fraudulent networks through visually representing connections between customers, payment methods, addresses and more.

Here’s an example of an ATO network.

![connect ATO example](https://storage.googleapis.com/ravelin-website-assets-production/assets/images/Screenshot-2024-12-19-at-08.53.58.png)  
In Connect, when an account is reclaimed, **we reset the network connections around the customer in question**.

We remove all connections with the account from before the reclaim date. However, these connections will be rebuilt after the reclaim if the customer reuses a device, email or card.

This means that a genuine customer will no longer appear to be in a fraudulent network once they have securely reclaimed their account.

![reclaimed account on Connect](https://storage.googleapis.com/ravelin-website-assets-production/assets/images/Reclaimed-customer-account-on-Connect.png)Here's another example. Above, one device has been used to access four accounts (ZM, XT, YG and VM). ZM has been identified as a fraudster.

After the fraud team restored access of account VM to its genuine owner and ensured the fraudster can no longer access it, they have marked the account as a reclaimed account.

You can see a **small round arrow on top of the VM circle**, indicating visually that this account has been reclaimed and handed back to its rightful owner.

**Please [get in touch](https://www.ravelin.com/contact-us) to learn more about our ATO solutions.**

##   
Further resources

- [Webinar video on-demand: Account takeover insights with Shawn Colpitts](https://pages.ravelin.com/account-takeover-insights-webinar)
- [Case study: Food marketplace reduces ATO by 95% with Ravelin](https://www.ravelin.com/blog/how-did-a-food-marketplace-reduce-account-takeovers-by-95)
- [Account security solutions](https://www.ravelin.com/solutions/account-security)
- [Ravelin Insights: Account Takeover Fraud](https://www.ravelin.com/insights/account-takeover-fraud)

## Author

![Jessica Allen](https://storage.googleapis.com/ravelin-website-assets-production/assets/images/_avatarSmall/3491/Screen-Shot-2019-08-13-at-16.12.52.webp)

Jessica AllenHead of Content (Ravelin alumna)

Jessica previously served as Head of Content at Ravelin.

[More from this author](https://www.ravelin.com/author/jessica-allen)

## Related content

[Blog / Press release

### Driven by AI, customers now rival criminals for ecommerce fraud, say merchants

Global ecommerce fraud enters a new phase as losses continue to climb. Merchants now view criminals and their own customers as presenting a comparable risk, and there's a gap in AI adoption.

![Ravelin Symbol Blue 1](https://storage.googleapis.com/ravelin-website-assets-production/assets/images/_33x33_crop_center-center_none_ns/187712/Ravelin-Symbol-Blue-1.webp)Ravelin Technology](https://www.ravelin.com/blog/ravelin-fraud-survey-2026-press-release)

[Blog / Payments &amp; payment fraud

### Safeguarding agentic commerce – fraud strategy advice by Ravelin's CPO

"If there’s anything fraudsters like, it’s a new thing." Here's how to protect your online shop from agentic commerce fraud – which can target you no matter whether you're actively adopting AI shopping or not.

![RAVELIN STAFF Mark Barlow Head Of product website](https://storage.googleapis.com/ravelin-website-assets-production/assets/images/_33x33_crop_center-center_none_ns/175066/RAVELIN_STAFF_Mark_Barlow_Head_Of_product_website.webp)Mark Barlow,Chief Product Officer](https://www.ravelin.com/blog/agentic-commerce-fraud-prevention-strategy-analysis)

[Blog / Ravelin product

### Next-level reporting with Ravelin: Introducing Insights and AI-powered queries

Discover how the new Insights section and AI-powered queries in the Ravelin Dashboard simplify your fraud reporting.

![Ashleigh](https://storage.googleapis.com/ravelin-website-assets-production/assets/images/_33x33_crop_center-center_none_ns/267519/ashleigh.webp)Ashleigh Luccini Gilera,Senior Product Marketing Manager](https://www.ravelin.com/blog/fraud-reporting-insights-ai-queries)
